Route breach-record naming policy through Commercial Use Agreement, not License
Revises V1C1 §7.4 per maintainer instruction: the License no longer sets a named-by-default disclosure rule for published breach/termination records. Instead, whether a Commercial Entitlement holder is named is governed exclusively by the applicable Commercial Use Agreement — a bilaterally negotiated contract where informed consent can actually be obtained. The License itself only guarantees an anonymized Phase-and-category fallback where no Commercial Use Agreement addresses it or none exists (e.g. a noncommercial Section 2(c) breach). This meaningfully reduces the License text's own legal exposure: the open item is no longer "should the License name parties by default" but "the not-yet-drafted Commercial Use Agreement template needs its own naming/consent/data-protection clause" — recommended as a future TRSL-CommercialUseAgreement-Draft.md deliverable, analogous to the CLA recommendation already on record. Updates Appendix A item 10, OpenQuestions-WorkingDefaults.md Q12 item 5, PRD FR-10, and TSD §4.1 to match. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
parent
236ebc2509
commit
c12a4043c4
5 changed files with 24 additions and 6 deletions
|
|
@ -165,7 +165,7 @@ Status `canonical` requires documented review; Stage 0 may ship them as `registe
|
|||
2. Conversion already triggered remains irrevocable (Rule 9) even if a later dispute reduces Development Credit — shortfall is a commercial/audit matter, not re-restriction.
|
||||
3. When the Trust Service operator is also a Phase licensor, attestations must be independently re-computable offline; public metrics must not depend on private operator judgment.
|
||||
4. **(Added 2026-07-29, TRSL V1C1 §7.4)** Breach notices, cure status, and termination determinations for a Phase are published by the Trust Service as a public conformity signal, distinguishing `alleged` from `determined`. Publication is a ministerial record of the Licensor's (or a dispute process's) determination — the Trust Service does not itself decide whether a breach occurred.
|
||||
5. **(Added 2026-07-29, TRSL V1C1 Appendix A item 10 — blocked on legal)** Whether the published breach record names the affected party by default (the mechanism's intended deterrent effect) or falls back to an anonymized Phase-and-category record, and how that interacts with Commercial Use Agreement confidentiality, defamation law, and data-protection law. This is the single most legally sensitive open item introduced by V1C1.
|
||||
5. **(Revised 2026-07-29, TRSL V1C1 §7.4 / Appendix A item 10 — blocked on legal)** Whether a published breach record names the affected Commercial Entitlement holder is governed by the applicable Commercial Use Agreement, not a License-wide default — the License itself only guarantees an anonymized Phase-and-category fallback where no Commercial Use Agreement addresses it or none exists. The open item is now drafting the Commercial Use Agreement template's own naming/consent/data-protection clause, not a License-text decision.
|
||||
|
||||
**Blocked on governance:** Full dispute SLA and third-party auditor program (PRD Phase 7).
|
||||
|
||||
|
|
|
|||
|
|
@ -253,7 +253,7 @@ The Trust Service's five core responsibilities — Phase Registry, Extension Reg
|
|||
- Public records expose aggregate Development/Remission Credit, Outstanding Target, applicable extensions, and conversion status without customer-identifying detail.
|
||||
- Confidential evidence (contracts, invoices, receipts) is accessible only to authorized audit/dispute parties.
|
||||
- Private commercial data is never required to be uploaded to the Trust Service.
|
||||
- **(Added 2026-07-29)** Breach and termination determinations under `specs/TargetRevenueSourceLicense-V1C1.md` §7.4 are published as a distinct public conformity signal; whether the affected party is named by default is an open, legally sensitive question (`specs/OpenQuestions-WorkingDefaults.md` Q12 item 5) and is not resolved by this requirement.
|
||||
- **(Revised 2026-07-29)** Breach and termination determinations under `specs/TargetRevenueSourceLicense-V1C1.md` §7.4 are published as a distinct public conformity signal, with an anonymized Phase-and-category fallback by default; whether a Commercial Entitlement holder is named is governed by the applicable Commercial Use Agreement, a separate deliverable not yet drafted (`specs/OpenQuestions-WorkingDefaults.md` Q12 item 5).
|
||||
|
||||
### FR-11 — Successive Phases
|
||||
|
||||
|
|
|
|||
|
|
@ -116,7 +116,7 @@ The Licensor may declare a new Phase covering subsequent improvements to the Sof
|
|||
|
||||
A breach that You dispute, and that has not been finally determined, shall be recorded as **alleged**; it shall be recorded as **determined** only once the cure period has run without cure, or the dispute has been resolved against You under the applicable Commercial Use Agreement's dispute process, if any. The Trust Service shall update the record promptly upon resolution in either direction. Recording an alleged or determined breach under this Section 7.4 is a ministerial act of publishing the Licensor's determination (or a dispute process's outcome); it does not give the Trust Service discretionary authority to decide whether a breach occurred, consistent with Section 5.4's evidence-not-cause principle.
|
||||
|
||||
Where the affected party is a Commercial Entitlement holder, the public record identifies that party by name, unless the applicable Commercial Use Agreement or applicable law requires otherwise, in which case the record states the Phase and breach category without naming the party. [Candidate note: this naming default is the specific mechanism the Licensor intends for ecosystem accountability — see Appendix A item 10, flagged **[LEGAL, OPEN]** as the most legally sensitive item in this candidate: it interacts with confidentiality terms in Commercial Use Agreements, defamation law, and data-protection law where the affected party is an individual.]
|
||||
Whether, and under what conditions, the public record identifies a Commercial Entitlement holder by name is governed exclusively by the applicable Commercial Use Agreement, which the Licensor and that Commercial Entitlement holder negotiate and agree to directly. This License does not itself set a naming default. Where no Commercial Use Agreement addresses the question, or where the affected party has no Commercial Use Agreement at all (for example, a Section 2(c) breach by a Noncommercial Use licensee), the public record states the Phase and breach category only, without naming the party. [Candidate note: routing the naming policy through the bilaterally-negotiated Commercial Use Agreement, rather than setting a License-wide default, was a deliberate 2026-07-29 revision — see Appendix A item 10. It moves the mechanism's legal exposure (defamation, data-protection, confidentiality) into a contract where informed consent can actually be obtained from the affected party, instead of a unilateral term in a public license that also binds parties who never negotiated anything.]
|
||||
|
||||
[Candidate note: cure-period length and structure modeled on the norm observed across BSL 1.1, FSL, and Elastic License 2.0 in `history/260729-TRSL-PriorArt-Survey.md` §2; whether a cured violation should also generate a Target Ledger entry is flagged **[OPEN]** in Appendix A.]
|
||||
|
||||
|
|
@ -161,8 +161,8 @@ This appendix is not part of the operative license text. It tracks what must be
|
|||
| 7 | (all) | Full review under German AGB law (Transparenzgebot) and, where applicable, EU consumer-protection law | **[LEGAL]** | `history/260729-TRSL-Jurisdiction-StandardTerms.md` §1–§2 |
|
||||
| 8 | (all) | Contributor rights sufficient to grant this License and the Future License (CLA) | **[LEGAL]**, separate deliverable | `history/260729-TRSL-ContributorRights-Research.md` §4 |
|
||||
| 9 | (all) | Full specialist legal review in every jurisdiction of intended use | **[LEGAL]** | `specs/TargetRevenueLicenseConcept.md` §21.5 |
|
||||
| 10 | §7.4 | Naming-by-default policy for published breach records: interaction with Commercial Use Agreement confidentiality terms, defamation law, and data-protection law where the affected party is an individual. Added 2026-07-29 at maintainer request, specifically to provide reputational/ecosystem-signal pressure toward conformity — this is a deliberate design choice, not an oversight, but its exact mechanics are the newest and least-reviewed clause in this candidate. | **[LEGAL, OPEN]** — highest priority among new items | This document §7.4; no prior research task covered public breach disclosure specifically |
|
||||
| 10 | §7.4 | Commercial Use Agreement template must include a naming/disclosure clause governing whether a breach record identifies the Commercial Entitlement holder, with appropriate consent, confidentiality-carve-out, and data-protection handling — this License defers the policy but does not itself draft it. | **[LEGAL]**, separate deliverable | This document §7.4; no Commercial Use Agreement template yet exists in this repository |
|
||||
|
||||
**On item 10:** this is the one place in the candidate where the Licensor has chosen a specific mechanism (named public disclosure by default) ahead of dedicated legal research, because the mechanism's *value* — ecosystem trust signal and conformity pressure — depends on the party being identifiable, not merely on a breach existing in the abstract. Before V1.0, confirm at minimum: (a) whether Commercial Use Agreements can lawfully waive confidentiality for this specific purpose; (b) whether a "determined" breach (cure period lapsed, or dispute resolved) provides sufficient factual basis to avoid defamation exposure across the jurisdictions in scope; (c) whether the affected party's status as an individual (sole proprietor, contractor) triggers data-protection obligations (e.g., GDPR) that the anonymized fallback in §7.4 must handle by default rather than by exception.
|
||||
**On item 10:** §7.4 intentionally does not set a naming default in the License itself — naming policy is routed to the Commercial Use Agreement, a bilaterally negotiated contract where the affected party can give informed consent (or negotiate confidentiality) rather than being bound by a unilateral public-license term. This meaningfully reduces the License text's own legal exposure, but it does not eliminate the underlying question: a Commercial Use Agreement template still needs a clause addressing (a) whether Commercial Use Agreements may lawfully make named disclosure a condition of the Commercial Entitlement; (b) whether a "determined" breach (cure period lapsed, or dispute resolved) provides sufficient factual basis to avoid defamation exposure across the jurisdictions in scope; (c) data-protection obligations (e.g., GDPR) where the Commercial Entitlement holder is an individual. Recommend a dedicated `TRSL-CommercialUseAgreement-Draft.md` deliverable, analogous to the CLA research recommendation in `history/260729-TRSL-ContributorRights-Research.md` §6, when a Commercial Use Agreement template becomes an active near-term need.
|
||||
|
||||
**Promotion path:** per `SCOPE.md` §4 and `workplans/TREV-WP-0001-license-prior-art-research.md` T06, this candidate requires explicit human acceptance before being treated as adequate briefing material for counsel, and specialist legal sign-off on every item above before any candidate may be published as official Version 1.0.
|
||||
|
|
|
|||
|
|
@ -208,7 +208,7 @@ Per `specs/TargetRevenueLicenseConcept.md` §14.2, every Trust Service component
|
|||
| Attestation | Publish a signed statement once the ledger fold reaches zero | Requiring its own publication as a condition of conversion |
|
||||
| Breach/Compliance Record | Publish the Licensor's breach notices, cure status, and termination determinations for a Phase, distinguishing `alleged` from `determined` (`specs/TargetRevenueSourceLicense-V1C1.md` §7.4) | Independently deciding whether a breach occurred — that determination is the Licensor's, or a dispute process's, never the Trust Service's own judgment |
|
||||
|
||||
**New in V1C1 (2026-07-29):** the Breach/Compliance Record component is a license-driven addition, not yet reflected in a Stage 0 schema — WP-0002 shipped before this clause existed. Schema and pure-fold treatment (if any is needed; this is a record-publication concern, not a Target-Ledger fold input) are deferred to the Trust Service PRD (`specs/ProductRequirementsDocument.md` §11.1 item 8), not added retroactively to WP-0002's scope. The naming-policy question in V1C1 Appendix A item 10 must be resolved before this component's public/confidential evidence tiering (§14.5) can be finalized.
|
||||
**New in V1C1 (2026-07-29):** the Breach/Compliance Record component is a license-driven addition, not yet reflected in a Stage 0 schema — WP-0002 shipped before this clause existed. Schema and pure-fold treatment (if any is needed; this is a record-publication concern, not a Target-Ledger fold input) are deferred to the Trust Service PRD (`specs/ProductRequirementsDocument.md` §11.1 item 8), not added retroactively to WP-0002's scope. The License itself sets the public/confidential default (anonymized Phase-and-category record unless a Commercial Use Agreement provides for named disclosure — V1C1 §7.4); the still-open item is drafting that Commercial Use Agreement's own naming/consent clause (V1C1 Appendix A item 10), not this component's evidence tiering.
|
||||
|
||||
---
|
||||
|
||||
|
|
|
|||
|
|
@ -246,3 +246,21 @@ A item 10; `OpenQuestions-WorkingDefaults.md` Q12 item 5). Propagated to
|
|||
`specs/TechnicalSpecificationDocument.md` §4.1 (new Breach/Compliance
|
||||
Record Trust Service component) and `specs/ProductRequirementsDocument.md`
|
||||
FR-10. Still `todo` — ready for continued human review.
|
||||
|
||||
Result 2026-07-29 (maintainer revision): maintainer requested naming-policy
|
||||
specifics be routed through the Commercial Use Agreement rather than set
|
||||
as a License-wide default. Revised §7.4: the License now only guarantees
|
||||
an anonymized Phase-and-category fallback record; whether a Commercial
|
||||
Entitlement holder is named is governed exclusively by the applicable
|
||||
Commercial Use Agreement (bilaterally negotiated, informed-consent basis)
|
||||
or, absent one (e.g. a noncommercial §2(c) breach), stays anonymized by
|
||||
default. This meaningfully reduces the License text's own legal exposure —
|
||||
the open item shifts from "should the License name parties by default"
|
||||
to "the Commercial Use Agreement template needs its own naming/consent/
|
||||
data-protection clause," recommended as a future
|
||||
`TRSL-CommercialUseAgreement-Draft.md` deliverable analogous to the CLA
|
||||
recommendation in `history/260729-TRSL-ContributorRights-Research.md` §6.
|
||||
Propagated to `OpenQuestions-WorkingDefaults.md` Q12 item 5,
|
||||
`specs/ProductRequirementsDocument.md` FR-10, and
|
||||
`specs/TechnicalSpecificationDocument.md` §4.1. Still `todo` — ready for
|
||||
continued human review.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue